CVE-2023-28461
CISA 기관 조치 기한: 2024-12-16
Array Networks AG/vxAG ArrayOS
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
KEV 필수 조치: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
벡터: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H